CVE-2024-37365

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Nov 12, 2024
CWE ID 20

Summary

CVE-2024-37365 is a newly identified remote code execution vulnerability. This issue arises from a flaw in the affected product that enables users to save projects in the public directory. An attacker with local access can manipulate these files, potentially deleting or modifying them to their advantage. Worse still, a malicious user could exploit this vulnerability to escalate their privileges by introducing malicious macros that execute arbitrary code. This security flaw poses a significant risk to systems and must be addressed promptly with the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share